Bulletproof Hosting Provider Aeza Group Shifting Their Infrastructure to New Autonomous System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Following U.S. Treasury sanctions imposed on July 1, 2025, the notorious bulletproof hosting provider Aeza Group has rapidly migrated its infrastructure to a new autonomous system in an apparent attempt to evade enforcement measures.  Cybersecurity researchers at Silent Push detected …

New Phishing Attack Mimics Facebook Login Page to Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A rapidly evolving campaign is using a Browser-in-the-Browser (BitB) overlay to impersonate Facebook’s login and siphon user credentials. The lure hinges on a deceptive CAPTCHA challenge that seamlessly morphs into a counterfeit Facebook session window, duping victims across desktops and …

Malicious Android Apps Mimic as Popular Indian Banking Apps Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are weaponizing India’s appetite for mobile banking by circulating counterfeit Android apps that mimic the interfaces and icons of public-sector and private banks. Surfacing in telemetry logs on 3 April 2025, the impostors travel through smishing texts, QR codes …

Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated espionage campaign dubbed “Fire Ant” demonstrates previously unknown capabilities in compromising VMware virtualization infrastructure.  Since early 2025, this threat actor has systematically targeted VMware ESXi hosts, vCenter servers, and network appliances using hypervisor-level techniques that evade traditional endpoint …

New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly uncovered campaign is exploiting gamers’ enthusiasm for off-beat indie titles to plant credential-stealing malware on machines. Branded installers for nonexistent games such as “Baruda Quest,” “Warstorm Fire,” and “Dire Talon” are pushed through slick YouTube trailers and Discord …

xonPlus Launches Real-Time Breach Alerting Platform For Enterprise Credential Exposure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chennai, India, July 25th, 2025, CyberNewsWire xonPlus, a real-time digital risk alerting system, officially launches today to help security teams detect credential exposures before attackers exploit them. The platform detects data breaches and alerts teams and systems to respond instantly. …

Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm-2603, which has been deploying Warlock ransomware in compromised environments.  The vulnerabilities affect on-premises SharePoint Server 2016, …

New CastleLoader Attack Using Cloudflare-Themed Clickfix Technique to Infect Windows Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CastleLoader, a rapidly evolving loader discovered in 2025, has surged across underground networks by weaponizing Cloudflare-themed “Clickfix” phishing pages and doctored GitHub repositories to compromise Windows hosts. The malware masquerades as benign developer resources, browser updates, or meeting portals, luring …

Hive0156 Hackers Attacking Government and Military Organizations to Deploy Remcos RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Russian-aligned threat actor known as Hive0156 has intensified its cyber espionage campaigns against Ukrainian government and military organizations, deploying the notorious Remcos Remote Access Trojan through carefully crafted social engineering attacks. The group has demonstrated remarkable persistence in …

Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spoofed Microsoft SharePoint notifications have been a familiar lure for corporate users, but a wave of campaigns traced between March and July 2025 shows a sharp uptick in both volume and sophistication. The operators register look-alike domains such as “sharepoint-online-docs-secure[.]co” …